Formidable Form Builder for WordPress versions before 2.05.03 contains a stored cross-site scripting caused by insufficient input sanitization and output escaping in form parameters like 'after_html', letting unauthenticated attackers inject and execute arbitrary scripts in victims' browsers
id: CVE-2017-20192
info:
name: Formidable Forms < 2.05.02 - Cross-Site Scripting
author: 0xanis
...